Release GnuPG 2.5.22
Open, NormalPublic

Assigned To
None
Authored By
• werner
Jul 2 2026, 3:16 PM
Subscribers

Description

Noteworthy changes in version 2.5.22 (2026-08-31)

  • New and extended features:
    • gpg: New option "primary" for the --card-edit "generate" command. This option is useful to create only the primary key on the first slot of an OpenPGP card. [T8344]
    • Make detection of the installation directory work for macOS. [rG0be940905d]
    • gpgsm: Emit issuer and serial no. when the certificate is not found. [T8363]
  • Bug fixes:
    • gpg: Fix trustdb recursive lock problem. [T8317]
    • gpg: Fix using wrong fingerprint length for the intended recipient fingerprint. [T8330]
    • gpg: Fix wrong assertion edge case in building packets. [rGe319d82d7e]
    • gpg: Fix possible double free in import_revoke_cert. [T8328]
    • gpg: Fix long standing regression of "bkuptocard". [T8344,rGf103eaee63]
    • gpg: Fix TOFU trust models to actually check UTK signatures. [T8404]
    • gpg: Don't enable the partial file guard if already done. Fix regression introduced by partial file guards. [T8399]
    • gpgsm: Only display de-vs compliance status in de-vs compliance mode. [T8333]
    • gpgsm: Return 0 if decryption of multi recipient file succeeds. [T8340]
    • gpgsm: Check args for special file names and dashes. [T8347]
    • gpgsm: Fix keydb_get_flags with keyboxd. [T8048]
    • g13: Add sanity check on the syntax of the dmsetup algo string. [rG386c3e63b1]
  • Other changes:
    • gpg,gpgsm: Emit signing time as status output also for bad signatures. [T8364]
    • gpg: Emit status line for failed write. [T8398]
    • scd: Put a workaround for buggy CCID device. [T8331]
    • scd: Allow switching APP when --pcsc-shared is enabled. [rGf783c02525]
    • gpgconf: Print a warning on Windows on insufficent global config directory permissions. [rG56eb3148c7]

(prev: T8262 next: T8425)

Related Objects

Mentioned In
T8425: Release GnupG 2.5.23
T8262: Release GnuPG 2.5.21
Mentioned Here
T8425: Release GnupG 2.5.23
rGe319d82d7e3a: gpg: Fix assertion.
rGf103eaee63f7: gpg: Fix long standing regression of "bkuptocard"
rG0be940905d70: common: Make unix_rootdir work for macOS.
rGf783c02525c3: scd: Allow switching APP when opt.pcsc_shared is enabled.
rG386c3e63b1ca: g13: Add sanity check on the syntax of the dmsetup algo string.
rG56eb3148c7b8: gpgconf: Print a warning on Windows on insufficent /etc permissions.
T8048: Keyboxd: S/MIME certificate is imported on ldap search
T8317: Recursive trustdb lock problem
T8328: double keydb_release() in error handling path of g10/import.c : import_revoke_cert
T8331: scd: Support Nitrokey 3
T8333: Kleopatra: S/MIME decryption fails for certs with crl check problems
T8340: GpgSM: Decryption with multiple recipients emits a failure, if the first pinenty is cancelled
T8344: gpg: Fix edit-key bkuptocard
T8347: GpgSM: Verification of detached signature via pipe fails
T8363: gpgsm should print issuer and serial no. of unknown signing certificates as status information
T8364: gpg does not emit creation time of bad signatures
T8398: Kleopatra: No error is given when decrypted file can not be saved due to full disk
T8399: No file saved on decryption if signing certificate is not available
T8404: gpg's TOFU trust model allows authentication bypass
rG245330ebeaf6: scd:openpgp: Fix CHV1 retry counter byte index.
rGab9ce5f5e775: w32:common: Fix usleep in w32_wait_when_sharing_violation.
rG4c7e68cf3d33: gpgsm: Require a minimum tag length for GCM decryption.
rGca25a7a61beb: scd: Fix condition to retrieve ATR.
T7873: Decrypt to foo.gpg.part files and rename
T8029: IPC error on batch import of secret kyber cert
T8188: gpgsm: No error/warning on verification or decryption in case of trusted but not VS-compliant certificate
T8252: Use RECP_FPR subpacket for standalone designated revocations.
T8261: GnuPG: Assert in gpgconf fails on change of keyserver option, if value includes a comma
T8277: Potential use-after-free in keygen when handling keyserver option
T8281: scd: Have a limit for data object handling
T8303: Heap OOB reads in dirmngr DNS CERT/DANE parsing
T8262: Release GnuPG 2.5.21

Event Timeline

• werner triaged this task as Normal priority.Jul 2 2026, 3:16 PM
• werner created this task.
• werner created this object with edit policy "Administrators".
• werner updated the task description. (Show Details)
• werner renamed this task from Release GnuPG 2.5.22 to Release GnuPG 2.5.23.Jul 2 2026, 3:47 PM
• werner renamed this task from Release GnuPG 2.5.23 to Release GnuPG 2.5.22.Jul 2 2026, 3:49 PM
• werner updated the task description. (Show Details)